Denial of Service Vulnerability in dnsmasq by Red Hat
CVE-2026-13002

4.4MEDIUM

What is CVE-2026-13002?

A flaw has been detected in the dnssec.c library of the dnsmasq service, which could lead to an infinite loop when processing responses from a DNSSEC-signed zone. An attacker can exploit this vulnerability by sending a specially crafted DNS response, resulting in the dnsmasq process becoming unresponsive. This effectively halts DNS resolution services for clients relying on dnsmasq, disrupting network operations and affecting accessibility.

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Lennart Espe for reporting this issue.
.